Job Description
Job Summary
L1: This position will lead the design, implementation, governance and continuous improvement of Microsoft Intune and enterprise endpoint management services across corporate, BYOD, co-managed and cloud-native endpoints.
L2: The Intune Architect is expected to possess advanced hands-on expertise in Microsoft Intune administration and architecture, endpoint security, Windows Autopilot, application deployment, compliance policy design, Microsoft Graph based automation, DevOps integration and L3/L4 operational support. The role will work closely with workplace engineering, security, infrastructure, application, operations and customer stakeholders to translate requirements into scalable endpoint management standards and controls.
Key Responsibilities
- Design, implement and govern enterprise-scale Microsoft Intune solutions for Windows, macOS, iOS/iPadOS and Android Enterprise devices.
- Define endpoint management strategy including device enrollment, provisioning, configuration, compliance, security baseline, application deployment and lifecycle management standards.
- Design and govern Windows Autopilot, BYOD, corporate-owned device, unattended enrollment and co-management models with SCCM/MECM where applicable.
- Configure and govern device configuration profiles, compliance policies, Conditional Access policies, App Protection policies, endpoint security policies and data protection controls.
- Design and optimize Intune application deployment standards including packaging requirements, assignment models, detection logic, deployment rings, troubleshooting methods and rollback practices.
- Manage and support Windows Update rings, feature updates, Office 365 updates, evergreen servicing and Autopatch aligned endpoint compliance improvement.
- Design and support device configurations including Wi-Fi, VPN, certificate-based authentication, LDAP/Active Directory related dependencies, CA integration and required Intune console configurations.
- Build and maintain automation frameworks using PowerShell, Microsoft Graph API and other scripting approaches for provisioning, compliance checks, reporting, remediation and decommissioning.
- Develop self-healing and proactive remediation scripts to reduce repetitive operational effort and improve endpoint compliance posture.
- Implement DevOps practices for endpoint configuration management including Git version control, Azure DevOps/GitHub Actions pipelines and Infrastructure-as-Code approaches such as Terraform or Bicep where suitable.
- Support Zero Trust endpoint security architecture by defining security baselines, compliance controls, vulnerability remediation inputs and monitoring requirements.
- Provide L3/L4 technical leadership for complex Intune, Autopilot, application deployment, compliance, enrollment and Windows provisioning issues, including high-severity P1/P2 scenarios.
- Create and maintain architecture documents, SOPs, technical standards, operational readiness plans, knowledge transfer artefacts and governance frameworks.
- Collaborate with security, infrastructure, application, workplace engineering and service operations teams to ensure endpoint services remain secure, scalable, supportable and aligned to service levels.
- Mentor engineers and administrators, conduct technical workshops, support upskilling initiatives and drive continuous service improvement.
Skill Requirements
- Strong experience in administration, architecture and configuration of Microsoft Intune enterprise environments.
- Deep knowledge of Microsoft Endpoint Manager, Microsoft Entra ID, Conditional Access, MDM, MAM, Defender for Endpoint and endpoint compliance controls.
- Hands-on experience with Windows Autopilot, Windows 10/11 provisioning, unattended enrollment, device lifecycle management and troubleshooting.
- Expertise in PowerShell scripting and Microsoft Graph API based automation for Intune management, reporting and remediation.
- Working knowledge of Python, Bash, Azure DevOps, GitHub Actions, Git version control and DevOps operating models for endpoint configuration management.
- Experience with application deployment through Intune, deployment optimization, detection rules, app delivery troubleshooting and software distribution governance.
- Experience with Windows 11 evergreen support, Windows and Office feature updates, update rings, Autopatch concepts, availability, performance optimization and reporting.
- Understanding of SCCM/MECM co-management, cloud-native endpoint strategies and migration from legacy endpoint management platforms such as Workspace ONE to Microsoft Intune.
- Knowledge of endpoint security baselines, compliance posture management, vulnerability remediation planning and integration with tools such as Defender for Endpoint, Qualys, Nexthink, SIEM or equivalent platforms.
- Ability to manage technical teams and support Intune services either as a technical lead or individual contributor.
- Experience handling and driving P1/P2 situations from an Intune and Windows device management perspective.
- Experience in enterprise transformation, operational readiness, release readiness, service recovery, reporting dashboards, AI-assisted automation or Power BI based insights will be an added advantage.
Other Requirements
- Strong stakeholder management with the ability to lead architecture discussions, technical workshops and governance forums.
- Ability to translate complex technical topics into clear business, customer and operational language.
- Customer-focused approach with demonstrable experience delivering services to defined service levels and improving operational stability.
- Strong analytical thinking, problem-solving ability and capability to drive issues to successful closure.
- Ability to work effectively in an operational environment alongside technical, security, application and infrastructure teams.
- Initiative-taking mindset with ability to learn and apply modern technologies, automation practices and endpoint security improvements.
- Strong written and verbal communication skills, attention to detail and self-motivation.
- Ability to build positive working relationships with customers and internal stakeholders with a focus on consistent service excellence.
- Ability to mentor, coach and upskill engineers while building reusable knowledge assets and operational standards.
Required Experience
- 15+ years of overall experience in Endpoint Management, Workplace Services, IT Infrastructure, Mobility, Modern Workplace or related enterprise technology services.
- 10+ years of hands-on experience with Microsoft Intune and Microsoft Endpoint Management technologies.
- Experience designing, implementing or governing large-scale enterprise endpoint management solutions.
- Strong understanding of enterprise security, compliance, cloud transformation and Microsoft 365 environments.
- Experience leading modernization or migration initiatives, operational transition, endpoint governance or global Windows device management services is preferred.
Preferred Certifications:
- Microsoft Certified: Endpoint Administrator Associate (MD-102).
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Microsoft Certified: DevOps Engineer Expert (AZ-400).
- Microsoft Certified: Enterprise Administrator Expert or Cybersecurity Architect Expert.
- ITIL Foundation certification will be advantageous.
- Azure AI, Security, Compliance and Identity fundamentals certifications will be an added advantage.
Key Deliverables:
- Intune Architecture and Governance Framework.
- Endpoint Security Design and compliance baseline standards.
- Windows Autopilot and device enrollment strategy.
- Device Compliance and Conditional Access Framework.
- Application Deployment Standards and deployment governance model.
- Automation roadmap for device lifecycle, compliance remediation, reporting and operational efficiency.
- Modern Workplace Transformation Roadmap.
- SOPs, technical standards, knowledge transfer and operational readiness documentation.